Policies configuration

Create a Policy

An Active Discovery policy is a list of settings that define protocols and their parameters that will be used to inspect the industrial network. The policy will be applied to a network, an IP address, an IP range, or a preset and used on a list of sensors and components.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies .

Step 2

Click + Create policy.


What to do next

Set Active Discovery Broadcast

Before you begin

Active Discovery is compatible with the following Broadcast protocols:

  • Beckhoff

  • BACnet

  • EtherNet/IP

  • Siemens S7

  • Profinet

  • ICMPv6

The sensor will send requests on all defined interfaces.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies .

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

In the Broadcast Configuration field, enable the toggle switch for the required fields.

Step 5

The Broadcast retry and Unicast timeout (in seconds) are listed under Advanced settings.

  1. Leave the Broadcast retry and Unicast timeout (in seconds) at their default values (3 and 10).

    Broadcast retry: number of request attempts.

    Unicast timeout (in seconds): waiting time in seconds for a response.

Step 6

Click Create.


What to do next

Set Active Discovery Unicast

Set Active Discovery Unicast

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select a protocol.

Step 5

Update Advanced settings.

Step 6

Click Create.


Set Active Discovery Unicast BACnet

Set Active Discovery Unicast BacNet to search for devices and components with BacNet requests. All components with an IPV4 address will be queried.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select BACnet.

Step 5

Enable the toggle switch.

Step 6

Click Create.


Set Active Discovery Unicast Beckhoff

Enable Active Discovery Unicast Beckhoff to search for devices and components using AMS requests. It will check all components with an IPV4 address.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select Beckhoff.

Step 5

Enable the toggle switch.

Step 6

(Optional) Enable Authentication and enter a Beckhoff user account and password.

Without authentication, Cyber Vision will only be able to provide the device name and firmware version.

Step 7

Click Create.


Set Active Discovery Unicast DNP3

Set Active Discovery Unicast DNP3 to search for devices and components with DNP3 requests. All components with an IPV4 address will be queried.

Before you begin

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select DNP3.

Step 5

Enable the toggle switch.

Step 6

Leave the Source Address and Max Destination Address at their default values (0 and 16).

Step 7

Click Create.


Set Active Discovery Unicast EtherNet/IP

Set Active Discovery Unicast Ethernet/IP to search for devices and components with Ethernet/IP requests. All components with an IPV4 address will be queried.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select EtherNet/IP.

Step 5

Enable the toggle switch.

Step 6

Check the checkbox to enable the Backplane discovery button.

Active Discovery will look for different module details within the discovered chassis.

Step 7

Click Create.


Set Active Discovery Unicast GESRTP

Configure Active Discovery Unicast GESRTP to search for devices and components using GESRTP requests. It will check all components with an IPV4 address.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select GESRTP.

Step 5

Enable the toggle switch.

Step 6

Click Create.


Set Active Discovery Unicast HTTP or HTTPS

Configure Active Discovery Unicast HTTP/HTTPS to find devices and components with HTTP/HTTPS requests. It will check all components with an IPV4 address.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select HTTP/HTTPS.

Step 5

Enable the toggle switch.

Step 6

Add HTTP or HTTPS port details to scan.

Step 7

Click Create.


Set Active Discovery Unicast Melsoft

Set Active Discovery Unicast Melsoft to search for devices and components with Melsoft requests. All Mitsubitshi components with an IPV4 address will be queried.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select Melsoft.

Step 5

Enable the toggle switch.

Step 6

Click Create.


Set Active Discovery Unicast MMS

Set Active Discovery Unicast MMS to search for devices and components using MMS requests. The Manufacturing Message Specification (MMS) is used between IEDs and SCADA devices.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select MMS.

Step 5

Enable the toggle switch.

Step 6

Click Create.


Set Active Discovery Unicast Modbus

Set Active Discovery Unicast Modbus to search for devices and components with Modbus requests. All components with an IPV4 address will be queried.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select Modbus.

Step 5

Enable the toggle switch.

Step 6

Add the Unit Id code (0-255), (usually 0).

Step 7

Select the Force UMAS Function Codes option to discover with UMAS.

In this case, Modbus discovery performs UMAS commands even if it does not detect the device as a Schneider Electric PLC.

Step 8

Click Create.


Set Active Discovery Unicast OMRON

Set Active Discovery Unicast OMRON to search for devices and components with FINS requests. All components with an IPV4 address will be queried.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select OMRON.

Step 5

Enable the toggle switch.

Step 6

Click Create.


Set Active Discovery Unicast SiemensS7

Set Active Discovery Unicast SiemensS7 to search for devices and components with SiemensS7 requests. SiemensS7 is a communication protocol used on Siemens PLCs. Siemens PLCs with an IPV4 address will be queried.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select SiemensS7.

Step 5

Enable the toggle switch.

Step 6

Click Create.


Set Active Discovery Unicast SiemensS7plus

Set Active Discovery Unicast SiemensS7plus to search for devices and components with SiemensS7plus requests. SiemensS7plus is a communication protocol used on the latest Siemens PLCs. Siemens PLCs with an IPV4 address will be queried.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select SiemensS7plus.

Step 5

Enable the toggle switch.

Step 6

Click Create.


Set Active Discovery Unicast SNMPv2c

Set Active Discovery Unicast SNMPv2c to search for devices and components with SNMPv2c requests. All components with an IPV4 address will be queried. Default OIDs are requested for all devices and some specific OIDs are requested based on the vendor and the type of components.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select SNMPv2c.

Step 5

Enable the toggle switch.

Step 6

Enter a Community string for authentication.

IT or network administrators define the Community string. The value 'public' is often used by default

Step 7

Check the checkbox to enable the Enable SNMPv1 fallback option.

In case of failure with SNMPv2, SNMPv1 will be used.

Step 8

Click Create.


Refer to the annex appended at the end of this document to see the examples of unicast SNMPv2c results and detailed information about packets.

Set Active Discovery Unicast SNMPv3

Set Active Discovery Unicast SNMPv3 to search for devices and components with SNMPv3 requests. All components with an IPV4 address will be queried. Default OIDs are requested for all devices and some specific OIDs are requested based on the vendor and the type of components.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select SNMPv3.

Step 5

Enable the toggle switch.

Step 6

Type a community string for authentication.

IT or network administrators define community string. The value "public" is often used by default.

Step 7

Select the appropriate security and privacy level based on information provided by IT or network administrators.

All options available on SNMPv3 are implemented in . Three security levels are available:

  • Disable both authentication and privacy.

    Only a username is requested for authentication.

  • Enable authentication and disable privacy.

    Authentication uses HMAC-MD5 or HMAC-SHA algorithms.

    Select the algorithm to use and provide a username and an authentication password.

  • Enable both authentication and privacy.

    In addition to the previous level, a DES or AES encryption of the content is requested. Select the level of encryption to use and provide a username and an authentication password. In addition, you must provide a password used for the encryption.

Step 8

Click Create.


Refer to the Annex appended at the end of this document to see examples of Unicast SNMPv3 results and detailed information about packets.

Set Active Discovery Unicast WMI

Set Active Discovery Unicast WMI (Windows Management Instrumentation) to collect Windows information like local-host names and operating system versions.

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click + Create policy.

The Create a policy side panel appears.

Step 3

Enter a policy name in the Name field.

Step 4

Under Unicast configuration, click the drop-down arrow next to Add a new protocol and select WMI.

Step 5

Enable the toggle switch.

Step 6

Enter the Username and Password with appropriate WMI rights.

You can also use an Active Directory user account for authentication across multiple hosts with a single set of login credentials.

Step 7

Click Create.


Edit, Duplicate, and Delete Policy

Procedure


Step 1

From the main menu, choose Admin > Active Discovery > Policies.

Step 2

Click the policy name under the Name column that you want to modify.

The policy panel appears with the configurations and the Edit, Duplicate, and Delete buttons.

Step 3

If you click Edit, an Edit a policy panel appears.

  1. Edit the policy name in the Name field.

  2. Under the Broadcast configuration field, you can toggle the buttons ON/OFF to enable/disable broadcast protocols.

  3. Under Unicast configuration, click the drop-down arrow next to Add a new protocol field and select a protocol.

  4. Update Advanced settings.

  5. Click Update.

Step 4

If you click Duplicate, a Create a policy panel appears.

  1. Edit the policy name in the Name field.

  2. Under the Broadcast configuration field, you can toggle the buttons ON/OFF to enable/disable broadcast protocols.

  3. Under Unicast configuration, click the drop-down arrow next to Add a new protocol field and select a protocol.

  4. Update Advanced settings.

  5. Click Create.

Step 5

If you click Delete, a DELETE POLICY pop-up appears.

  1. Click Ok.